Title: Teydea Login Security &#8211; Password Policy, Complexity Rules &amp; Expiration
Author: Teydea Studio
Published: <strong>Апрель 19, 2024</strong>
Last modified: Август 27, 2026

---

Search plugins

![](https://ps.w.org/password-requirements/assets/banner-772x250.jpg?rev=3669579)

![](https://ps.w.org/password-requirements/assets/icon.svg?rev=3669579)

# Teydea Login Security – Password Policy, Complexity Rules & Expiration

 By [Teydea Studio](https://profiles.wordpress.org/teydeastudio/)

[Download](https://downloads.wordpress.org/plugin/password-requirements.3.8.0.zip)

[Live Preview](https://os.wordpress.org/plugins/password-requirements/?preview=1)

 * [Details](https://os.wordpress.org/plugins/password-requirements/#description)
 * [Reviews](https://os.wordpress.org/plugins/password-requirements/#reviews)
 *  [Installation](https://os.wordpress.org/plugins/password-requirements/#installation)
 * [Development](https://os.wordpress.org/plugins/password-requirements/#developers)

 [Support](https://wordpress.org/support/plugin/password-requirements/)

## Description

**Teydea Login Security lets you define and enforce password policies for all users
on your WordPress site.**

Set rules for password length, complexity (uppercase, lowercase, digits, special
characters), restricted characters, password expiration, and more. The plugin validates
passwords on login, registration, password changes, and during active sessions automatically
redirecting users to reset non-compliant passwords.

**Key benefits:**

 * Enforce password length and complexity rules from a single settings page.
 * Set password expiration to ensure users update their passwords regularly.
 * Require users to confirm their current password before making changes.
 * Compatible with WordPress multisite networks.

Whether you manage a personal blog, a membership site, or a multisite network, Teydea
Login Security helps you maintain consistent password standards across all user 
accounts.

Learn more at [teydeastudio.com/plugins/login-security](https://teydeastudio.com/plugins/login-security/?utm_source=Teydea+Login+Security).

**Why password policies matter**

Weak passwords remain one of the most common entry points for unauthorized access
to WordPress sites. Teydea Login Security lets you enforce the password-policy controls
that many security and compliance programs call for minimum length, character composition,
expiration, restricted characters, and more across every user account. It helps 
you apply these controls, but does not by itself make your site compliant with any
particular standard.

### Features

#### Free Features

 * **Minimum password length** Set and enforce the minimum number of characters 
   for user passwords.
 * **Maximum password length** Cap the number of characters a password may contain,
   keeping passwords within a length your site and any systems you integrate with
   accept.
 * **Password complexity rules** Require a mix of uppercase letters, lowercase letters,
   digits, special characters, and a minimum number of unique characters.
 * **Consecutive username symbols** Restrict how many consecutive characters from
   the user’s username or display name can appear in the password. Matching ignores
   letter case.
 * **Restricted characters** Block specific characters from being used in passwords.
 * **Restricted words and phrases** Maintain a site-wide list of words and phrases(
   one per line) that passwords cannot contain. Case-insensitive substring matching
   catches site-specific tokens such as your brand name, product names, your city,
   or a year token (for example: `acme`, `summer`, `2026`).
 * **Maximum password age** Force users to update their passwords periodically (
   e.g., every 30 days).
 * **Minimum password age** Prevent users from changing their password too frequently,
   discouraging rapid cycling back to an old password.
 * **Require current password** Add a Current Password” field to the user profile
   screen and validate it before allowing password changes.
 * **Custom password hints** Replace the default WordPress password hint with a 
   policy-specific hint based on active rules.
 * **Site Health integration** A Site Health test reports whether your plugin settings
   are properly configured.
 * **Multisite/network support** Works with both standard and multisite WordPress
   installations.
 * **[AI integration](https://teydeastudio.com/plugins/login-security/features/ai-integration/?utm_source=Teydea+Login+Security)**
   On WordPress 6.9+ with the [MCP Adapter](https://wordpress.org/plugins/mcp-adapter/)
   plugin, list, configure, and delete password policies through natural language
   commands from any connected AI provider.
 * **Translation-ready** Localize the plugin into any language.

#### PRO Features

 * **[Prevent password reuse](https://teydeastudio.com/plugins/login-security/features/passwords-reuse-prevention/?utm_source=Teydea+Login+Security)**
   Block users from reusing their previous passwords, encouraging new, unique passwords
   every time.
 * **[Custom password policies per role or user](https://teydeastudio.com/plugins/login-security/features/dedicated-policies-by-user-and-or-role/?utm_source=Teydea+Login+Security)**
   Assign different password rules for administrators, editors, WooCommerce customers,
   or specific users.
 * **[Block common, weak passwords](https://teydeastudio.com/plugins/login-security/features/restricted-passwords-list/?utm_source=Teydea+Login+Security)**
   Over 100,000 common passwords are blocked, preventing users from choosing easy-
   to-guess passwords.
 * **Breached password screening (HaveIBeenPwned)** Screen passwords against the
   HaveIBeenPwned Pwned Passwords” breach corpus using k-anonymity, so users cannot
   pick a password already exposed in a data breach. The full password never leaves
   your server.
 * **Password expiry warning emails** Warn users by email on a schedule you configure
   before their password expires, so they can change it before being locked out.
 * **Vendor-default account detection** Scan user accounts for risky patterns default
   or predictable usernames, logins matching your domain, and unchanged display 
   names and review or dismiss each finding from a dedicated settings tab, a dashboard
   widget, and admin notices.
 * **Integrations**:
    - **[WooCommerce integration](https://teydeastudio.com/plugins/login-security/integrations/woocommerce/?utm_source=Teydea+Login+Security)**
      Enforce password policies on WooCommerce login, registration, checkout account
      creation (including Store API), account details, password change, and password
      reset forms. Replaces WooCommerce’s built-in password strength meter with 
      your policy rules.
    - **[Ultimate Member integration](https://teydeastudio.com/plugins/login-security/integrations/ultimate-member/?utm_source=Teydea+Login+Security)**
      Enforce password policies within Ultimate Member registration, login, password
      reset, and password change forms. Disables Ultimate Member’s built-in password
      strength option to avoid conflicts.
    - **[Tutor LMS integration](https://teydeastudio.com/plugins/login-security/integrations/tutor-lms/?utm_source=Teydea+Login+Security)**
      Enforce password policies on Tutor LMS student and instructor registration,
      login, password change, and password reset forms.
    - **[LifterLMS integration](https://teydeastudio.com/plugins/login-security/integrations/lifterlms/?utm_source=Teydea+Login+Security)**
      Enforce password policies on LifterLMS registration (including checkout), 
      account password change, and password reset forms. Replaces LifterLMS’s built-
      in password strength meter with your policy rules.
    - **[LearnPress integration](https://teydeastudio.com/plugins/login-security/integrations/learnpress/?utm_source=Teydea+Login+Security)**
      Enforce password policies on LearnPress registration, login, and password 
      change forms.
    - **[Sensei LMS integration](https://teydeastudio.com/plugins/login-security/integrations/sensei-lms/?utm_source=Teydea+Login+Security)**
      Enforce password policies on Sensei LMS registration and login forms.
    - **[BuddyPress integration](https://teydeastudio.com/plugins/login-security/integrations/buddypress/?utm_source=Teydea+Login+Security)**
      Enforce password policies on BuddyPress registration, login, and password 
      change forms.
    - **[bbPress integration](https://teydeastudio.com/plugins/login-security/integrations/bbpress/?utm_source=Teydea+Login+Security)**
      Enforce password policies on bbPress login and profile password change forms.
      Replaces bbPress’s built-in password strength meter with your policy rules.
 * **Priority support and updates** Get premium email support and updates.

Learn more about the PRO version at [teydeastudio.com/plugins/login-security/pricing](https://teydeastudio.com/plugins/login-security/pricing/?utm_source=Teydea+Login+Security).

### Video Tutorial

See the plugin in action:

### Related Plugins

Looking for a way to force users to reset their passwords immediately? Check our
[Teydea Password Reset](https://wordpress.org/plugins/password-reset-enforcement/)
plugin it lets you require password resets site-wide, by role, or for individual
users, with WP-CLI support for automation.

## Screenshots

[⌊Password policy settings: activate the policy, name it, and choose which rules
to enforce.⌉⌊Password policy settings: activate the policy, name it, and choose 
which rules to enforce.⌉[

Password policy settings: activate the policy, name it, and choose which rules to
enforce.

[⌊Rule settings: minimum and maximum password length, password age, and complexity
requirements.⌉⌊Rule settings: minimum and maximum password length, password age,
and complexity requirements.⌉[

Rule settings: minimum and maximum password length, password age, and complexity
requirements.

[⌊Enabled rules: each password policy rule can be switched on or off individually.⌉⌊
Enabled rules: each password policy rule can be switched on or off individually.⌉[

Enabled rules: each password policy rule can be switched on or off individually.

[⌊Restricted words and phrases: block site-specific words from appearing in passwords.⌉⌊
Restricted words and phrases: block site-specific words from appearing in passwords
.⌉[

Restricted words and phrases: block site-specific words from appearing in passwords.

[⌊Enforcement on the user profile screen: the current password is required to set
a new one.⌉⌊Enforcement on the user profile screen: the current password is required
to set a new one.⌉[

Enforcement on the user profile screen: the current password is required to set 
a new one.

[⌊Enforcement on the password reset form: policy hints and a clear error when the
password is not compliant.⌉⌊Enforcement on the password reset form: policy hints
and a clear error when the password is not compliant.⌉[

Enforcement on the password reset form: policy hints and a clear error when the 
password is not compliant.

## Installation

 1. Upload the `password-requirements` directory to `/wp-content/plugins/`, or install
    the plugin through the WordPress plugins screen directly.
 2. Activate the plugin through the Plugins” menu in WordPress.
 3. Go to Settings” > Login Security” to configure your password policy.
 4. Enable the rules you need, adjust their settings, and save. Your password policy
    is now active.

## FAQ

### How do I access the settings?

After activation, go to Settings” > Login Security” in the WordPress admin. The 
settings page lets you enable or disable individual rules and configure their values.

### What happens when a user’s password does not meet the policy?

On login, the user is redirected to the password reset form. On password change 
or registration, a clear error message explains which rules the password does not
meet.

### How are accented and non-Latin characters counted?

Length and unique-character rules count characters, not bytes. hasło” counts as 
five characters, the same as any five-letter password written in plain ASCII. The
consecutive-symbols limit for the username and display name is counted in characters
too. One caveat: when an accent is typed as a separate combining mark rather than
as a single accented character, the letter and the mark count as two characters.

### Does this plugin work with WooCommerce?

WooCommerce integration is available in the PRO version. It enforces password policies
on WooCommerce login, registration, checkout account creation (including Store API),
account details, password change, and password reset forms. It also replaces WooCommerce’s
built-in password strength meter with your policy rules.

### Does it work with LMS plugins like LifterLMS, Tutor LMS, LearnPress, or Sensei LMS?

Yes. The PRO version includes integrations for LifterLMS, Tutor LMS, LearnPress,
and Sensei LMS. Password policies are enforced on registration, login, and password
change forms within these plugins. See the [integrations page](https://teydeastudio.com/plugins/login-security/integrations/?utm_source=Teydea+Login+Security)
for details.

### Is the plugin compatible with WordPress multisite?

Yes. Teydea Login Security supports both standard WordPress installations and multisite
networks.

### Can I set different password rules for different user roles?

Yes, with the PRO version you can create multiple password policies and assign them
to specific user roles or individual users.

### What is the difference between the free and PRO versions?

The free version provides a single global password policy with length, complexity,
age, restricted characters, restricted words and phrases, and current password requirements.
The PRO version adds per-role and per-user policies, password reuse prevention, 
a blocklist of over 100,000 common passwords, breached password screening via HaveIBeenPwned,
password expiry warning emails, vendor-default account detection, and integrations
with WooCommerce, Ultimate Member, LifterLMS, Tutor LMS, LearnPress, Sensei LMS,
BuddyPress, and bbPress. See the [pricing page](https://teydeastudio.com/plugins/login-security/pricing/?utm_source=Teydea+Login+Security)
for details.

### Where can I find the unminified source code?

All source ships with the plugin: the plugin’s own JavaScript is in `src/`, and 
the bundled `@teydeastudio/components` and `@teydeastudio/utils` libraries are in`
deps/js/components/src/` and `deps/js/utils/src/`. To rebuild, install Node.js 20
and run `npm install && npm run build` in the plugin directory.

## Reviews

![](https://secure.gravatar.com/avatar/d591892f0f685c06b937f291ababdec6100195a2e44df09b6b4efff66e7a8020?
s=60&d=retro&r=g)

### 󠀁[Excellent plugin with prompt and thorough support](https://wordpress.org/support/topic/excellent-plugin-with-prompt-and-thorough-support/)󠁿

 [kmeyer9999](https://profiles.wordpress.org/kmeyer9999/) Январь 16, 2026

This plugin lets me implement an appropriate level of security on my site to protect
users' privacy and potential financial data by ensuring all users have a strong 
password in place. There are many easy-to-use options to vary the strength requirements,
and the messages to the user spell out the requirements in a simple-to-understand
sentence. Support for this plugin is AWESOME, they respond quickly and thoroughly,
and are keen to make sure the plugin handles any odd scenario you come across. I
highly recommend this plugin to anyone who needs to ensure a level of password strength
on their wordpress site.

 [ Read all 1 review ](https://wordpress.org/support/plugin/password-requirements/reviews/)

## Contributors & Developers

“Teydea Login Security – Password Policy, Complexity Rules & Expiration” is open
source software. The following people have contributed to this plugin.

Contributors

 *   [ Teydea Studio ](https://profiles.wordpress.org/teydeastudio/)
 *   [ Bartosz Gadomski ](https://profiles.wordpress.org/bartoszgadomski/)

[Translate “Teydea Login Security – Password Policy, Complexity Rules & Expiration” into your language.](https://translate.wordpress.org/projects/wp-plugins/password-requirements)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/password-requirements/),
check out the [SVN repository](https://plugins.svn.wordpress.org/password-requirements/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/password-requirements/)
by [RSS](https://plugins.trac.wordpress.org/log/password-requirements/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 3.8.0 (2026-08-28)

 * Password policy hint is now shown wherever WordPress sets a password – on the
   Add New User, Profile and Edit User screens, in addition to the password reset
   form
 * Passwords WordPress generates for new accounts now satisfy the active policy,
   so a user handed a generated password can sign in with it instead of being sent
   straight to a forced reset
 * Fixed the consecutive user name symbols rule: the configured number is now the
   number of symbols allowed, matching the help text; a limit of 0 no longer rejects
   every password of a covered user; matching now ignores letter case; and a short
   password that is a slice of the user name is no longer let through
 * Password length and uniqueness rules now count characters rather than bytes, 
   so accented and non-Latin passwords are measured consistently. A password that
   met the minimum length on its byte count alone is no longer compliant, and the
   user will be asked to change it at their next login
 * Restricted words and phrases, and the user name checks, now behave the same regardless
   of the server character encoding: entries and passwords are handled as UTF-8,
   malformed input is rejected on save and repaired on load, and a password containing
   undecodable characters can no longer slip past either check
 * The minimum password age no longer blocks a password change the plugin itself
   compels, which could leave an account locked out between the two rules
 * The password hint on the reset form now describes the account being reset rather
   than the visitor’s own session
 * The zero-limit warning under the consecutive symbols field is no longer shown
   for an inactive policy
 * Accessibility: removed the external OWASP link from the password hint and the
   special characters help text, and fixed the label and help text associations 
   across the settings screen form controls
 * Markup moved out of translatable strings, so translators receive words only
 * Password policies published through the Abilities API now carry a title and description
   for every field
 * Compatibility with WordPress 7.1 confirmed
 * Plugin assets and screenshots updated
 * Dependencies updated
 * Code improvements

#### 3.7.2 (2026-07-17)

 * Security: fixed a privilege escalation vulnerability where a crafted request 
   to the password reset form could assign any role, including Administrator, to
   an existing account. Exploiting it required a valid password reset link for an
   account the attacker already controls
 * Fixed an error on sites running PHP 7.4 caused by PHP 8.0+ syntax in the password
   compliance check; PHP 7.4 compatibility is restored

#### 3.7.1 (2026-07-13)

 * Fixed an issue on the login and password-change screens when another plugin passes
   an empty login message
 * Dependencies updated
 * Code improvements

#### 3.7.0 (2026-06-22)

 * Security hardening: tightened REST error responses and policy-context role validation(
   defense-in-depth audit follow-up)
 * New Restricted words and phrases” list: define site-wide words and phrases that
   passwords may not contain, with a per-policy on/off toggle
 * Settings page tabs are now reflected in the URL, so a tab can be bookmarked and
   shared
 * Added a clear admin notice for unmet server requirements (minimum PHP/WordPress
   version, required extensions)
 * Dependencies updated
 * Code improvements

#### 3.6.3 (2026-05-12)

 * Wording improvements re: minimum unique characters” field
 * Updated the notice behavior to display as error” rather than a message”
 * Documented source code location in readme.txt (added FAQ entry)
 * Dependencies updated
 * Code improvements

#### 3.6.2 (2026-04-16)

 * Compatibility with WordPress 7.0 confirmed
 * Dependencies updated
 * Formatting updates
 * Code improvements

#### 3.6.1 (2026-03-20)

 * Plugin icon and assets updated
 * Security hardening – added missing escaping
 * Dependencies updated

#### 3.6.0 (2026-03-14)

 * Abilities API implemented: password policies are now available in WordPress MCP
   server
 * Direct access protection added to all PHP files
 * Dependencies updated
 * Formatting updates
 * Unnecessary translation files removed since these are loaded from WordPress.org
 * Do not hardcode `wp-login.php` path for login form
 * Code improvements

#### 3.5.0 (2026-01-28)

 * Support for restricting certain characters in passwords implemented
 * Dependencies updated
 * Code improvements

#### 3.4.1 (2026-01-12)

 * Harden handling of the allow_password_reset” filter to improve compatibility 
   with third-party plugins

(For older records, see the `changelog.txt` file).

## Commercial plugin

This plugin is free but offers additional paid commercial upgrades or support.

## Meta

 *  Version **3.8.0**
 *  Last updated **1 month ago**
 *  Active installations **400+**
 *  WordPress version ** 6.6 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/password-requirements/)
 * Tags
 * [password policy](https://os.wordpress.org/plugins/tags/password-policy/)[password strength](https://os.wordpress.org/plugins/tags/password-strength/)
   [passwords](https://os.wordpress.org/plugins/tags/passwords/)[security](https://os.wordpress.org/plugins/tags/security/)
   [strong password](https://os.wordpress.org/plugins/tags/strong-password/)
 *  [Advanced View](https://os.wordpress.org/plugins/password-requirements/advanced/)

## Ratings

 5 out of 5 stars.

 *  [  1 5-star review     ](https://wordpress.org/support/plugin/password-requirements/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/password-requirements/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/password-requirements/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/password-requirements/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/password-requirements/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/password-requirements/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/password-requirements/reviews/)

## Contributors

 *   [ Teydea Studio ](https://profiles.wordpress.org/teydeastudio/)
 *   [ Bartosz Gadomski ](https://profiles.wordpress.org/bartoszgadomski/)

## Support

Issues resolved in last two months:

     1 out of 1

 [View support forum](https://wordpress.org/support/plugin/password-requirements/)